A nice way to copy stuff about and mount all kinds of drives — and the home of
the kubed/rclone image, a standardized backup / restore tool other apps
can drop in.
kubed/rclone wraps rclone/rclone with gpg and two streamed scripts so any
app can archive a directory to object storage and pull it back, encrypted, with
no plaintext ever touching disk:
tar the source dir → gpg encrypt → rclone rcat to the remoterclone cat → gpg decrypt → tar extract into a dirEverything is piped; the only on-disk state is a throwaway GPG keyring in a tmp
dir. The scripts don't care what's in the directory or how it got there — that's
the calling app's job. They only do tar + gpg + rclone. The rclone.conf (the
remote definition) is injected by the caller, never baked in.
Pick the mode with the first arg: backup or restore. Any other argument is
passed straight through, so the image still works as a plain rclone CLI.
| Var | backup | restore | Description |
|---|---|---|---|
REMOTE | ✓ | ✓ | rclone remote + bucket, e.g. gcs:backups.example.com |
SOURCE_DIR | ✓ | ✓ | directory to archive / extract back into |
PREFIX | remote folder (default: basename of SOURCE_DIR) | ||
RCLONE_FLAGS | extra rclone flags (e.g. --gcs-bucket-policy-only) | ||
GPG_RECIPIENT | ✓ | key id / email to encrypt to | |
GPG_PUBLIC_KEY | ✓ | armored public key, imported before encrypting | |
KEEP | backups to retain per prefix, 0 = all (default: 7) | ||
GPG_PRIVATE_KEY | ✓ | armored private key, imported before decrypting | |
GPG_PASSPHRASE | ✓ | passphrase protecting the private key | |
RESTORE_DIR | extract target (default: SOURCE_DIR) | ||
FILENAME | specific object to restore (default: latest) |
Backups are named <UTC-timestamp>.tar.gz.gpg (e.g.
2026-06-10T22:11:13.tar.gz.gpg). The timestamp is zero-padded and big-endian,
so a plain lexical sort == chronological — which is all "latest" and retention
rely on. The PREFIX folder identifies the source, so the name needs no prefix.
containers:
- name: backup
image: kubed/rclone:latest
args: [backup] # or: [restore]
env:
- name: REMOTE
value: gcs:backups.kubed.io
- name: SOURCE_DIR
value: /data
- name: RCLONE_FLAGS
value: --gcs-bucket-policy-only
# GPG_* + RCLONE_* creds injected from secrets
volumeMounts:
- { name: data, mountPath: /data }
- { name: rclone-conf, mountPath: /config/rclone }
alias rclone='op run --env-file="${CLUSTER_HOME}/apps/rclone/op.env" -- docker compose -f ${CLUSTER_HOME}/apps/rclone/docker-compose.yaml -p cluster run --rm --entrypoint rclone rclone'
rclone mount gcs:backups.kubed.io /data/backups --allow-other --vfs-cache-mode full --cache-dir=/data/cache1
rclone ls gcs:backups.kubed.io
rclone sync ./ gcs:backups.kubed.io --gcs-bucket-policy-only
from bucket to local dir
rclone sync gcs:backups.kubed.io ./ --gcs-bucket-policy-only
rclone cat gcs:backups.kubed.io/ldap/ldap.tar.gz.gpg
rclone copy ./ldap.tar.gz.gpg gcs:backups.kubed.io/ldap/ --gcs-bucket-policy-only
rclone cat gcs:backups.kubed.io/ldap/ldap.tar.gz.gpg | gpg --decrypt | tar xz -C ./data
rclone purge gcs:backups.kubed.io/ldap
Content type
Image
Digest
sha256:9481a4adc…
Size
38.8 MB
Last updated
4 months ago
docker pull kubed/rclone